🛡️ 每日安全情报
🛡️ AI 安全情报日报 · 2026-08-29
_2026-08-29 · 共筛出 139 条 ≥4★_
1. 2022_PoC-MSDT-Follina-CVE-2022-30190 exploit 🔓 ★★★★★
📋 Exploit for CVE-2022-30190. CVSS 9.3.
2. 4B5F5F4Bp exploit 🔓 ★★★★★
📋 Exploit for CVE-2017-0075. CVSS 7.6.
3. AI与云安全事件案例分析周报|2026.08.24 - 2026.08.28 🔓 ⚔️ 📄 ★★★★★
📋 原创 星云实验室 2026-08-28 18:14 北京 本周风险集中在高能力智能体失控后的横向协作、AI 基础设施被现实攻击流量穿透,以及本地模型与共享 GPU 的隔离边界失守。 事件一 OpenAI 针对 Hugging Face 事件
4. AI安全专题周报(20260828) 🔓 📄 ★★★★★
📋 报告编号: TIC-202608-AI03 报告周期: 2026年8月22日—8月28日 一、报告概述 基于360威胁情报中心对本期公开网络安全素材的整理与分析,本周AI安全风险主要集中在AI应用与Agent运行环境漏洞、提示注入和模型配置
5. AnySniff exploit 🔓 ★★★★★
📋 Exploit for CVE-2024-52940. CVSS 7.5.
6. BlackSnufkin exploit 🔓 ★★★★★
📋 Exploit for CVE-2025-52915 and CVE-2026-3609. CVSS 7.8.
7. COM-Code-Helper exploit 🔓 ★★★★★
📋 Exploit.
8. CVE-2014-8609-POC exploit 🔓 ★★★★★
📋 Exploit for CVE-2014-8609. CVSS 7.2.
9. CVE-2017-12636 exploit 🔓 ★★★★★
📋 Exploit for CVE-2017-12636. CVSS 9.
10. CVE-2018-17254 exploit 🔓 ★★★★★
📋 Exploit for CVE-2018-17254. CVSS 9.8.
11. CVE-2019-1006 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-1006. CVSS 7.5.
12. CVE-2019-14319 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-14319. CVSS 6.5.
13. CVE-2019-16278-Nostromo_1.9.6-RCE exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-16278. CVSS 9.8.
14. CVE-2019-2107 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-2107. CVSS 9.3.
15. CVE-2019-9465 exploit 🔓 ★★★★★
📋 Exploit for CVE-2019-9465. CVSS 5.5.
---
其他 124 条:
- CVE-2020-7842 exploit (5★)
- CVE-2021-22054 exploit (5★)
- CVE-2021-32159 exploit (5★)
- CVE-2021-32162 exploit (5★)
- CVE-2022-2274 exploit (5★)
- CVE-2022-22954-Testi exploit (5★)
- CVE-2022-24637 exploit (5★)
- CVE-2022-25018 exploit (5★)
- CVE-2022-44268 exploit (5★)
- CVE-2023-20052 exploit (5★)
- CVE-2023-21716-EXPLOIT.py (5★)
- CVE-2023-24249-Exploit (5★)
- CVE-2023-3163-SQL-Injection-Prevention exploit (5★)
- CVE-2023-31717 exploit (5★)
- CVE-2023-36845-Juniper-Vulnerability exploit (5★)
- CVE-2023-38831-Exploit-and-Detection (5★)
- CVE-2024-1247-PoC exploit (5★)
- CVE-2024-23897 exploit (5★)
- CVE-2024-30088 exploit (5★)
- CVE-2024-34144 exploit (5★)
- CVE-2024-6366 exploit (5★)
- CVE-2025-14700-poc exploit (5★)
- CVE-2025-24813 exploit (5★)
- CVE-2025-30208 exploit (5★)
- CVE-2025-32013 exploit (5★)
- CVE-2025-49113 exploit (5★)
- CVE-2025-57819-POC exploit (5★)
- CVE-2025-63420 exploit (5★)
- CVE-2026-11374-check exploit (5★)
- CVE-2026-25769 exploit (5★)
- CVE-2026-31283 exploit (5★)
- CVE-2026-33017 exploit (5★)
- CVE-2026-34197 exploit (5★)
- CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework (5★)
- CVE-2026-60121-CVE-2026-61498 exploit (5★)
- CVE-2026-62183 exploit (5★)
- CVE-2026-63030 exploit (5★)
- CVE-2026-63030-poc exploit (5★)
- CVE-2026-73673 exploit (5★)
- CVE-2026-9198 exploit (5★)
- CVE-Exploit-Research-Development-ITSOLERA (5★)
- CVE_2025_68413-4 exploit (5★)
- CWFF exploit (5★)
- Cisco-IOS-XE-CVE-2023-20198 exploit (5★)
- DockSec exploit (5★)
- Evil-Droid exploit (5★)
- Exploit for CVE-2026-10036 (5★)
- Exploit for Code Injection in Flowiseai Flowise (5★)
- Exploit for Code Injection in Mesop-Dev Mesop (5★)
- Exploit for Eval Injection in Langflow (5★)
- Exploit for Path Traversal in Jfrog Artifactory (5★)
- Exploits + Shellcode + GHDB (5★)
- Flowise-CVE-2025-58434-PasswordReset exploit (5★)
- FollinaExtractor exploit (5★)
- FreePBX-CVE-2025-57819 exploit (5★)
- Fsociety-CVE-2024-0670-CheckMK-LPE exploit (5★)
- G.O.S.S.I.P 阅读推荐 2026-08-28 CVE 仙人(工智能) (5★)
- GTScan exploit (5★)
- GodPotato exploit (5★)
- IBM: Unauthorized vertical privilege escalation vulnerability found on ibm.com endpoint (5★)
- IotShark exploit (5★)
- JSFScan.sh exploit (5★)
- Joomla-CMS-Full-Lifecycle-Pentest exploit (5★)
- Just a rumour of a bug is enough to find a security exploit these days (5★)
- Keylogger exploit (5★)
- Laravel-debug-Checker exploit (5★)
- Log4jTools exploit (5★)
- PHPunit-Exploit (5★)
- POC-CVE-2025-24813-Apache-Tomcat-Remote-Code-Execution exploit (5★)
- PaperCut Zero-Day Under Active Attack: Emergency Patch Released (5★)
- PoC--CVE-2019-10149_Exim exploit (5★)
- SBOM-VEX-Taint-Analysis exploit (5★)
- SecretFinder exploit (5★)
- SpooNMAP 长大了:发现报告、本地 LLM 检测,还有少得多的干等 (5★)
- Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth (5★)
- WebLogic-RCE-exploit (5★)
- WifiPassword-Stealer exploit (5★)
- Windows-7-EternalBlue-Exploitation (5★)
- WordPress: Author → stored XSS in wp-admin: unescaped sub-size filename from attachment metadata breaks out of the `src` attribute in `get_media_item()` (5★)
- awesome-mba exploit (5★)
- bad-dicom exploit (5★)
- batchql exploit (5★)
- byp4xx exploit (5★)
- cloud-sniper exploit (5★)
- creak exploit (5★)
- cve-2018-6574 exploit (5★)
- cve-2026-16219-croogo-lab exploit (5★)
- dcrawl exploit (5★)
- docker-tor-hiddenservice-nginx exploit (5★)
- ghostlock-vagrant-box exploit (5★)
- gtunnel exploit (5★)
- itsm-exploit (5★)
- js-driveby-download-CVE-2006-4777 exploit (5★)
- kraken exploit (5★)
- kyverno exploit (5★)
- lazyweb exploit (5★)
- metabase-sql-poc exploit (5★)
- metasploit-ldapnightmare exploit (5★)
- mitmproxy exploit (5★)
- multitor exploit (5★)
- nate158g-m-w-n-l-p-d-a-o-e exploit (5★)
- pdf.js-CVE-2024-4367 exploit (5★)
- phpsploit exploit (5★)
- pmg exploit (5★)
- pmkidcracker exploit (5★)
- pybeacon exploit (5★)
- sap_bo_launchpad-ssrf-timing_attack exploit (5★)
- shockwave-poc exploit (5★)
- smart-contract-security-training exploit (5★)
- the-book-of-secret-knowledge exploit (5★)
- tinyshell exploit (5★)
- velociraptor_CVE-2025-6264_PoC exploit (5★)
- whonow exploit (5★)
- wmi-static-spoofer exploit (5★)
- wp2shell exploit (5★)
- 【已复现】Nacos 管理接口权限绕过漏洞 (5★)
- 一个页面,看清应用从需求到上线的安全治理状态 (5★)
- 每周蓝军技术推送(2026.8.22-8.28) (5★)
- How to Rotate JWT Signing Keys Without Breaking Every Active Session (4★)
- Love Electric Breach: 877,000 Driver Records Offered for $600 (4★)
- 字节AI生产力,何以收进一个主干? (4★)
- 尽快修复! Nacos权限绕过漏洞 (4★)
- 管理智能体 AI(Agentic AI)的网络安全风险 (4★)
- 车主注意:Android 恶意软件攻击汽车中控主机 (4★)
🚨 漏洞预警
🔴 CRITICAL · 58 条
1. CVE-2026-9198 🔥 ⚡近期活跃 `CVSS 9.8`
🎯 受影响:IBM Langflow OSS 1.0.0 through 1.10.0
📋 简介:IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-9198
- https://www.ibm.com/support/pages/node/7278927
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198
- https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-YWH-JFELLUS-CVE-2026-9198&utm_source=rss&utm_medium=rss
- https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-RMHOWE425-POC-CVE-2026-9198&utm_source=rss&utm_medium=rss
2. CVE-2017-17485 🔥 ⚡近期活跃 `CVSS 9.8`
🎯 受影响:FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3
📋 简介:FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2017-17485
- http://www.securityfocus.com/archive/1/541652/100/0/threaded
- https://access.redhat.com/errata/RHSA-2018:0116
- https://access.redhat.com/errata/RHSA-2018:0342
- https://access.redhat.com/errata/RHSA-2018:0478
3. CVE-2025-24813 🔥 ⚡近期活跃 `CVSS 10.0`
🎯 受影响:Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information dis
📋 简介:Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2025-24813
- https://lists.apache.org/thread/j5fkjv2k477os90nczf2v9l61fb0kkgq
- http://www.openwall.com/lists/oss-security/2025/03/10/5
- https://lists.debian.org/debian-lts-announce/2025/04/msg00003.html
- https://security.netapp.com/advisory/ntap-20250321-0001/
4. CVE-2022-42889 🔥 ⚡近期活跃 `CVSS 9.8`
🎯 受影响:Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated
📋 简介:Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2022-42889
- http://packetstormsecurity.com/files/171003/OX-App-Suite-Cross-Site-Scripting-Server-Side-Request-Forgery.html
- http://packetstormsecurity.com/files/176650/Apache-Commons-Text-1.9-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2023/Feb/3
- http://www.openwall.com/lists/oss-security/2022/10/13/4
5. CVE-2026-73125 `CVSS 9.8`
🎯 受影响:Ebyte device web management interface does not consistently enforce
📋 简介:Ebyte device web management interface does not consistently enforce
authentication before granting access to administrative functionality.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-73125
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
6. CVE-2026-82266 `CVSS 9.8`
🎯 受影响:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting t
📋 简介:Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating unauthenticated requests as superusers.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82266
- https://github.com/redpanda-data/redpanda/issues/30989
- https://github.com/redpanda-data/redpanda
- https://github.com/redpanda-data/redpanda/blob/3cfce474a872090e7c74d14181885f5838c54cf2/conf/redpanda.yaml
- https://github.com/redpanda-data/redpanda/blob/3cfce474a872090e7c74d14181885f5838c54cf2/src/v/security/request_auth.cc
7. CVE-2026-33017 🔥 ⚡近期活跃 `CVSS 9.8`
🎯 受影响:Langflow
📋 简介:Langflow is a tool for building and deploying AI-powered agents and workflows.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-33017
- https://github.com/advisories/GHSA-rvqx-wpfh-mfx7
- https://github.com/langflow-ai/langflow/commit/73b6612e3ef25fdae0a752d75b0fabd47328d4f0
- https://github.com/langflow-ai/langflow/security/advisories/GHSA-vwmf-pq79-vjvx
- https://github.com/langflow-ai/langflow/releases/tag/1.8.2
8. CVE-2026-68929 `CVSS 9.3`
🎯 受影响:FastGPT
📋 简介:FastGPT is an open-source LLM platform for building AI applications on a knowledge base.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-68929
- https://github.com/labring/FastGPT/security/advisories/GHSA-q4pr-3qpg-9q5v
- https://github.com/labring/FastGPT/commit/81d391995b1f9989455267448872ff88bb1f42c9
9. CVE-2026-81578 `CVSS 8.8`
🎯 受影响:An improper access control vulnerability exists in the web management interface of PaperCut MF and P
📋 简介:An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81578
- https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
10. CVE-2026-61800 `CVSS 9.1`
🎯 受影响:Wazuh
📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-61800
- https://github.com/wazuh/wazuh/security/advisories/GHSA-3jff-488g-335f
- https://github.com/wazuh/wazuh/commit/f7f7c4d2d9e683c5d42e997fe7028a3fb2578853
11. CVE-2026-10036 🔥 `CVSS 8.8`
🎯 受影响:SpeechBrain
📋 简介:SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary code by supplying a crafted CKPT.yaml checkpoint metadata file parsed with PyYAML's unsafe loader during candidate enumeration in Checkpointer.recover_if_poss...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-10036
- https://github.com/SaiTeja-Erukude/CVE-2026-10036-speechbrain-rce
- https://github.com/speechbrain/speechbrain/releases/tag/v1.1.1
- https://github.com/speechbrain/speechbrain/pull/3067
- https://github.com/speechbrain/speechbrain/commit/22a616646a493871401461f80b2d5cf564cb2850
12. CVE-2022-30190 🔥 ⚡近期活跃 `CVSS 9.3`
🎯 受影响:A remote code execution vulnerability exists when MSDT
📋 简介:A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2022-30190
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190
- http://packetstormsecurity.com/files/167438/Microsoft-Office-Word-MSDTJS-Code-Execution.html
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30190
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30190
13. CVE-2026-18717 `CVSS 9.1`
🎯 受影响:ASE2000 2.35 through 2.37
📋 简介:ASE2000 2.35 through 2.37 is vulnerable to an improper certificate validation vulnerability, which may allow an attacker to impersonate the trusted peer, complete the TLS handshake, and read or modify protected communications.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18717
- http://www.ase-systems.com
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-04
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-04.json
14. CVE-2026-3627 `CVSS 9.1`
🎯 受影响:IBM Concert 1.0.0 through 2.3.1
📋 简介:IBM Concert 1.0.0 through 2.3.1 is vulnerable to SQL injection.
🔗 参考:
15. CVE-2026-75813 `CVSS 8.7`
🎯 受影响:Certain configuration endpoints may lack proper server-side
📋 简介:Certain configuration endpoints may lack proper server-side
authorization checks, allowing unauthorized users to access or modify
sensitive device settings.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-75813
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
16. CVE-2026-82017 `CVSS 8.6`
🎯 受影响:IGEL OS 12
📋 简介:IGEL OS 12 before 12.7.6 and IGEL OS 11 before 11.11.150 contain a boot registry parameter injection vulnerability that allows attackers with physical access to execute arbitrary Linux loader parameters by writing to an unencrypted and unsigned configuration area read by the s...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82017
- https://kb.igel.com/en/security-safety/current/isn-2026-19-code-execution-via-boot-registry
- https://blog.amberwolf.com/blog/2026/august/thin-client-thin-crypto-overview/
- https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Darren%20McDonald%20-%20Thin%20Client%20Thin%20Crypto%20-%20Bypassing%20Full-Desk%20Encryption%20Across%20Three%20Major%20Thin%20Clients%20Vendors%20without%20Breaking%20a%20Ci.pdf
- https://github.com/AmberWolfCyber/DEFCON34-ThinClientThinCrypto/blob/main/scripts/igel/inject_bootreg.py
17. CVE-2026-82283 `CVSS 8.6`
🎯 受影响:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing a
📋 简介:VoltAgent through 2.1.20 fails to validate conversation ownership in memory API handlers, allowing authenticated users to access other users' conversations.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82283
- https://github.com/VoltAgent/voltagent/issues/1371
- https://github.com/VoltAgent/voltagent
- https://github.com/VoltAgent/voltagent/blob/44b4c8e4998ce56095b2f0e4eaf1a988f5e6d0de/packages/server-core/src/handlers/memory.handlers.ts
- https://www.vulncheck.com/advisories/voltagent-memory-api-handlers-missing-ownership-checks
18. CVE-2026-54745 `CVSS 10`
🎯 受影响:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.
📋 简介:Kubeflow Pipelines enables users to build and deploy portable, scalable machine learning workflows.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54745
- https://github.com/kubeflow/pipelines/security/advisories/GHSA-gqww-5pj5-8fq7
- https://github.com/kubeflow/pipelines/pull/13511
- https://github.com/kubeflow/pipelines/commit/a35f97aa4c17b25572369e5022546ab4421bdbdd
- https://github.com/kubeflow/pipelines/releases/tag/2.17.0
19. CVE-2014-0160 🔥 ⚡近期活跃 `CVSS 7.5`
🎯 受影响:The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heart
📋 简介:The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2014-0160
- http://advisories.mageia.org/MGASA-2014-0165.html
- http://blog.fox-it.com/2014/04/08/openssl-heartbleed-bug-live-blog/
- http://cogentdatahub.com/ReleaseNotes.html
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD%202014-119-01
20. CVE-2026-18527 `CVSS 9.9`
🎯 受影响:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow
📋 简介:IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by ARE GUI component processing.
🔗 参考:
21. CVE-2026-54083 `CVSS 8.1`
🎯 受影响:Wazuh
📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54083
- https://github.com/wazuh/wazuh/security/advisories/GHSA-m4mf-qmhf-8vj6
- https://github.com/wazuh/wazuh/commit/e6ef99025b2ca4ba8003efb591c51545006bc2d4
22. CVE-2026-82291 `CVSS 8.1`
🎯 受影响:HeyForm
📋 简介:HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82291
- https://github.com/heyform/heyform/security/advisories/GHSA-fg7j-rmgr-rc9g
- https://github.com/heyform/heyform/blob/v3.0.0-rc.7/packages/server/src/main.ts
- https://github.com/heyform/heyform/commit/bf9d738ca70ae5641c0c7372982b00365c5144d4
- https://github.com/heyform/heyform
23. CVE-2026-19295 `CVSS 9.9`
🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1
📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system commands in the server process by saving a flow with a crafted type field value and triggering a build of a wrapper flow that references it.
🔗 参考:
24. CVE-2026-19286 `CVSS 9.8`
🎯 受影响:IBM Langflow OSS 1.0.0 through 1.11.1 could
📋 简介:IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint.
🔗 参考:
25. CVE-2026-82277 `CVSS 9.8`
🎯 受影响:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operatio
📋 简介:Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentication, authorization, or CSRF protection.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82277
- https://github.com/argoproj/argo-rollouts/issues/4747
- https://github.com/argoproj/argo-rollouts
- https://github.com/argoproj/argo-rollouts/blob/4e6a2798688e22868340d9871a3c8d78371f1568/server/server.go
- https://www.vulncheck.com/advisories/argo-rollouts-dashboard-unauthenticated-mutating-operations
26. CVE-2026-55068 `CVSS 9.3`
🎯 受影响:free5GC
📋 简介:free5GC is an open-source implementation of the 5G core network.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55068
- https://github.com/free5gc/free5gc/security/advisories/GHSA-x8mj-6p3q-g5pp
- https://github.com/free5gc/free5gc/issues/1056
- https://github.com/free5gc/nrf/pull/90
- https://github.com/free5gc/nrf/commit/bda0cf75be5556bb4c758c8b34710f3fe6bbe3ea
27. CVE-2026-55378 `CVSS 9.3`
🎯 受影响:JS Recon
📋 简介:JS Recon is a JavaScript enumeration and SAST tool.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55378
- https://github.com/js-recon/js-recon/security/advisories/GHSA-w9cj-mg3x-qjm4
- https://github.com/js-recon/js-recon/pull/121
- https://github.com/js-recon/js-recon/commit/447876c4bfa9ec5bc98cbc65d7a3e5f889412491
- https://github.com/js-recon/js-recon/releases/tag/v1.3.1-beta.2
28. CVE-2026-71187 `CVSS 9.8`
🎯 受影响:The Ebyte device relies on client side authentication logic that can be
📋 简介:The Ebyte device relies on client side authentication logic that can be
reproduced by unauthenticated users.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-71187
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
29. CVE-2026-82082 `CVSS 9.8`
🎯 受影响:NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remot
📋 简介:NUMail developed by Green-Computing has an OS Command Injection vulnerability.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82082
- https://www.twcert.org.tw/tw/cp-132-11144-45c6a-1.html
- https://www.twcert.org.tw/en/cp-139-11145-5361d-2.html
30. CVE-2026-82329 `CVSS 9.8`
🎯 受影响:JFrog Artifactory
📋 简介:JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82329
- https://docs.jfrog.com/releases/docs/jfrog-security-advisories
- https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases
31. CVE-2026-13086 `CVSS 9.3`
🎯 受影响:A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecate
📋 简介:A stack-based buffer overflow in the epm (Endpoint Protection Manager) service used by the deprecated Mobile Security feature in WatchGuard Fireware OS allows an unauthenticated remote attacker to execute arbitrary code.
🔗 参考:
32. CVE-2026-19313 `CVSS 9.3`
🎯 受影响:An heap overflow vulnerability in the WatchGuard Fireware OS iked process
📋 简介:An heap overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
🔗 参考:
33. CVE-2026-19315 `CVSS 9.3`
🎯 受影响:A type confusion vulnerability in the iked process of WatchGuard Fireware OS
📋 简介:A type confusion vulnerability in the iked process of WatchGuard Fireware OS allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
🔗 参考:
34. CVE-2026-19318 `CVSS 9.3`
🎯 受影响:A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process
📋 简介:A stack-based buffer overflow vulnerability in the WatchGuard Fireware OS iked process allows a remote unauthenticated attacker to execute arbitrary code by sending specially crafted network traffic.
🔗 参考:
35. CVE-2026-82244 `CVSS 9.4`
🎯 受影响:Budibase
📋 简介:Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82244
- https://github.com/Budibase/budibase/security/advisories/GHSA-gwr2-pgg3-p7xp
- https://www.vulncheck.com/advisories/budibase-before-3.41.3-remote-code-execution-via-plugin-eval
36. CVE-2026-55565 `CVSS 9.9`
🎯 受影响:Yamcs
📋 简介:Yamcs is a mission control framework.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55565
- https://github.com/yamcs/yamcs/security/advisories/GHSA-c64q-hj4j-375f
- https://github.com/yamcs/yamcs/commit/640e1598b7097b521692e89dd47a39b6cb1fc663
- https://github.com/yamcs/yamcs/commit/a8fb4a0693fa62a6eb729b26016d1090dd8b289c
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
37. CVE-2026-55634 `CVSS 9.9`
🎯 受影响:Pimcore
📋 简介:Pimcore is an Open Source Data & Experience Management Platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55634
- https://github.com/pimcore/pimcore/security/advisories/GHSA-9x44-4gxf-8c25
- https://github.com/pimcore/pimcore/pull/19183
- https://github.com/pimcore/pimcore/commit/a4f8c3cfee58b7d5fe4873d67782eff58dae9b9d
- https://github.com/advisories/GHSA-r2f4-ff2p-xc64
38. CVE-2026-55559 `CVSS 9.8`
🎯 受影响:Yamcs
📋 简介:Yamcs is a mission control framework.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55559
- https://github.com/yamcs/yamcs/security/advisories/GHSA-73mf-m39p-wpm9
- https://github.com/yamcs/yamcs/commit/549f295cf8c5496a5e799d6bec2432ef976c82aa
- https://github.com/yamcs/yamcs/commit/7192da1c49bdf5ab1d72e579a47766a7c43e87c8
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
39. CVE-2026-69658 `CVSS 9.8`
🎯 受影响:MQTT credentials and control traffic are transmitted in cleartext,
📋 简介:MQTT credentials and control traffic are transmitted in cleartext,
exposing sensitive information to network-level attackers.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-69658
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
40. CVE-2026-76179 `CVSS 9.8`
🎯 受影响:An improper protection of authentication tokens vulnerability exists in
📋 简介:An improper protection of authentication tokens vulnerability exists in
certain Ebyte gateway products.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-76179
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-237-06.json
41. CVE-2026-76943 `CVSS 9.8`
🎯 受影响:Xiiaozet LK100Wt
📋 简介:Xiiaozet LK100Wt contains an authentication weakness within an
administrative service that may allow an attacker to bypass intended
access controls and obtain command execution capabilities.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-76943
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json
42. CVE-2026-78032 `CVSS 9.8`
🎯 受影响:SOY CMS
📋 简介:SOY CMS contains an issue with deserialization of untrusted data.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-78032
- https://saitodev.co/article/7105
- https://jvn.jp/en/jp/JVN04485476/
43. CVE-2026-78239 `CVSS 9.8`
🎯 受影响:Xiiaozet LK100W exposes a critical management function that can be
📋 简介:Xiiaozet LK100W exposes a critical management function that can be
invoked without authentication, allowing a remote attacker to enable
administrative services that should be restricted.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-78239
- https://www.cisa.gov/news-events/ics-advisories/icsa-26-239-01
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-239-01.json
44. CVE-2026-54754 `CVSS 9.6`
🎯 受影响:Klever-Go
📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54754
- https://github.com/klever-io/klever-go/security/advisories/GHSA-p7gw-2pcp-5pf8
- https://github.com/klever-io/klever-go/commit/8bcc600b0ac88070740c63c7ce1c8a968dd85251
- https://github.com/klever-io/klever-go/releases/tag/v1.7.19
45. CVE-2026-54755 `CVSS 9.6`
🎯 受影响:Klever-Go
📋 简介:Klever-Go is the Go implementation of the Klever blockchain protocol.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54755
- https://github.com/klever-io/klever-go/security/advisories/GHSA-cgc5-v3f2-8m2v
- https://github.com/klever-io/klever-go/commit/8bcc600b0ac88070740c63c7ce1c8a968dd85251
- https://github.com/klever-io/klever-go/releases/tag/v1.7.19
46. CVE-2026-82078 `CVSS 9.4`
🎯 受影响:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCu
📋 简介:An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82078
- https://www.papercut.com/kb/Main/security-bulletin-27-aug-2026-urgent-security-advisory/
47. CVE-2026-55220 `CVSS 9.3`
🎯 受影响:Pimcore
📋 简介:Pimcore is an Open Source Data & Experience Management Platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55220
- https://github.com/pimcore/pimcore/security/advisories/GHSA-w23p-wrp7-ch38
- https://github.com/pimcore/pimcore/pull/19181
- https://github.com/pimcore/pimcore/commit/b184c01bf11e213e601d965b4e96c8bb7248e980
- https://github.com/pimcore/pimcore/releases/tag/v12.3.10
48. CVE-2026-78174 `CVSS 9.3`
🎯 受影响:WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagno
📋 简介:WatchGuard Dimension records unredacted session identifiers for logged-in users in its web UI diagnostic log.
🔗 参考:
49. CVE-2026-82090 `CVSS 9.2`
🎯 受影响:Pocket through 8.33.0.0
📋 简介:Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects external HTML into the DOM.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82090
- https://github.com/FUNFACTOR1/pocket-android-xss-0click-cve
50. CVE-2026-18918 `CVSS 9.1`
🎯 受影响:In Eclipse Lyo
📋 简介:In Eclipse Lyo versions 2.0.0 to 7.0.0, OAuth server authorization checks can be bypassed when the 2-legged auth is supported by the server.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-18918
- https://github.com/eclipse-lyo/lyo/releases/tag/v6.0.1.Final
- https://github.com/eclipse-lyo/lyo/releases/tag/v7.0.0.Beta3
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/221
51. CVE-2026-42007 `CVSS 9.1`
🎯 受影响:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigg
📋 简介:An attacker that has valid credentials can use a Sieve script with the editheader extension to trigger a use-after-free in the mail editing code, and to write memory contents beyond the intended buffer into the delivered mail.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-42007
- https://documentation.open-xchange.com/dovecot/security/advisories/csaf/2026/oxdc-adv-2026-0003.json
52. CVE-2026-50152 `CVSS 9.1`
🎯 受影响:Ceph
📋 简介:Ceph is an open-source distributed storage platform providing object, block, and file storage.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-50152
- https://github.com/ceph/ceph/security/advisories/GHSA-rg9p-5xcp-wm8h
- https://github.com/ceph/ceph/commit/d971bb2b6199f70b1708a20a63fa944ee7a94727
- https://github.com/ceph/ceph/commit/f2840d2fd338ab5de2865f0f78684bbf7b888c84
53. CVE-2026-55247 `CVSS 9.1`
🎯 受影响:plone.app.event provides the event content type for Plone. Prior to
📋 简介:plone.app.event provides the event content type for Plone.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55247
- https://github.com/plone/plone.app.event/security/advisories/GHSA-r82h-mqw3-fc56
- https://github.com/plone/plone.app.event/commit/1e3c83c15a24d1a789cdb012593505bc5620e28e
- https://github.com/plone/plone.app.event/commit/4de5eb3ea9e4f7f1781622e6d64fc086629d1437
- https://github.com/plone/plone.app.event/releases/tag/5.2.4
54. CVE-2026-55248 `CVSS 9.1`
🎯 受影响:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets. Prior t
📋 简介:plone.app.portlets provides portlets and a Plone-specific user interface for plone.portlets.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55248
- https://github.com/plone/plone.app.portlets/security/advisories/GHSA-x5g3-w747-2h8q
- https://github.com/plone/plone.app.portlets/commit/09da52ef7b297daa8e0cfd2361e47c37d9b073ad
- https://github.com/plone/plone.app.portlets/commit/9f16b6fb10211916686c6c346ea174bf517e3fbd
- https://github.com/plone/plone.app.portlets/commit/a3b2c2887165b308cd915cbb87b8276f90a76680
55. CVE-2026-55511 `CVSS 9.1`
🎯 受影响:Yamcs
📋 简介:Yamcs is a mission control framework.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55511
- https://github.com/yamcs/yamcs/security/advisories/GHSA-3g44-3m7x-cgg2
- https://github.com/yamcs/yamcs/commit/8c1070b12c0a6c003903325cb2a1013347e2dbde
- https://github.com/yamcs/yamcs/commit/b65a3d78178ba99a58b753feda6ecc3b5a694f13
- https://github.com/yamcs/yamcs/releases/tag/yamcs-5.12.8
56. CVE-2026-82281 `CVSS 9.1`
🎯 受影响:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_con
📋 简介:Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82281
- https://github.com/Cinnamon/kotaemon/issues/846
- https://github.com/Cinnamon/kotaemon
- https://github.com/Cinnamon/kotaemon/blob/9ad3e4e49aa35b8acddd235918a5d9753c1cfdf9/libs/ktem/ktem/pages/chat/control.py
- https://www.vulncheck.com/advisories/kotaemon-missing-ownership-check-in-conversation-functions
57. CVE-2026-40541 `CVSS 9`
🎯 受影响:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilit
📋 简介:An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows remote authenticated users, via a UI interaction, to read or write arbitrary files and conduct denial-of-se...
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-40541
- https://www.synology.com/en-global/security/advisory/Synology_SA_26_10
58. CVE-2026-82021 `CVSS 9`
🎯 受影响:Hermes Agent 0.18.2
📋 简介:Hermes Agent 0.18.2 prior to 0.19.0 contains a supply chain vulnerability in its bundled MCP catalog that allows a remote attacker to execute arbitrary code by compromising a third-party upstream repository referenced via a mutable branch rather than a pinned commit SHA.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82021
- https://github.com/NousResearch/hermes-agent/releases/tag/v2026.7.20
- https://github.com/NousResearch/hermes-agent/pull/64463
- https://github.com/NousResearch/hermes-agent/commit/9df5f879b4a5925c0f8f947e7e16ed8e845932c3
- https://www.vulncheck.com/advisories/hermes-agent-mcp-catalog-supply-chain-rce-via-mutable-branch-reference
🟠 HIGH · 10 条
1. CVE-2025-30156 `CVSS 8.9`
🎯 受影响:Ceph
📋 简介:Ceph is an open-source distributed storage platform providing object, block, and file storage.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2025-30156
- https://github.com/ceph/ceph/security/advisories/GHSA-7q3q-3975-qw3q
- https://github.com/ceph/ceph/commit/2ba086255de09c8b95177717cc7e9dd4377e2f0f
- https://github.com/ceph/ceph/commit/3078188a7bdd89e2975280f2a906c71c2f6effd6
2. CVE-2026-39944 `CVSS 8.8`
🎯 受影响:Ceph
📋 简介:Ceph is an open-source distributed storage platform providing object, block, and file storage.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-39944
- https://github.com/ceph/ceph/security/advisories/GHSA-j73r-qrgx-jvq2
- https://github.com/ceph/ceph/releases/tag/v19.2.6
- https://github.com/ceph/ceph/releases/tag/v20.2.4
3. CVE-2026-82282 `CVSS 8.8`
🎯 受影响:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticat
📋 简介:Atlantis through 0.47.1 fails to authenticate the /github-app/setup endpoint, allowing unauthenticated attackers to access GitHub App credentials.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82282
- https://github.com/runatlantis/atlantis/issues/6622
- https://github.com/runatlantis/atlantis
- https://github.com/runatlantis/atlantis/blob/12bfa59f44d8f65bfdda132bff61d8f8f29af1d6/server/controllers/github_app_controller.go
- https://github.com/runatlantis/atlantis/blob/12bfa59f44d8f65bfdda132bff61d8f8f29af1d6/server/middleware.go
4. CVE-2026-81517 `CVSS 8.7`
🎯 受影响:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance m
📋 简介:An unauthenticated party able to reach the port of a MongoDB Connector for BI (mongosqld) instance may generate enough routine connection log activity to exhaust the storage backing the configured log path.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-81517
- https://www.mongodb.com/docs/bi-connector/current/release-notes/
5. CVE-2026-54085 `CVSS 7.1`
🎯 受影响:Wazuh
📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-54085
- https://github.com/wazuh/wazuh/security/advisories/GHSA-mvh4-g699-984j
- https://github.com/wazuh/wazuh/commit/b7f3a5e59000e4cdef75f397f1107ae3e1c186a9
6. CVE-2026-55066 `CVSS 7.1`
🎯 受影响:Vikunja
📋 简介:Vikunja is an open-source self-hosted task management platform.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55066
- https://github.com/go-vikunja/vikunja/security/advisories/GHSA-5pg6-m483-7vrg
- https://github.com/go-vikunja/vikunja/pull/3239
- https://github.com/go-vikunja/vikunja/commit/36cdc2ce2be0b8ccc74227d178b92047d59cd65f
- https://github.com/go-vikunja/vikunja/releases/tag/v2.4.0
7. CVE-2026-55848 `CVSS 8.6`
🎯 受影响:mapfish-print
📋 简介:mapfish-print is a component of MapFish for printing templated cartographic maps.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-55848
- https://github.com/mapfish/mapfish-print/security/advisories/GHSA-5v29-34h8-v68r
- https://github.com/mapfish/mapfish-print/pull/4212
- https://github.com/mapfish/mapfish-print/pull/4215
- https://github.com/mapfish/mapfish-print/pull/4216
8. CVE-2026-82271 `CVSS 7.1`
🎯 受影响:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handl
📋 简介:R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authenticated users to modify other users' conversations.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82271
- https://github.com/SciPhi-AI/R2R/issues/2292
- https://github.com/SciPhi-AI/R2R
- https://github.com/SciPhi-AI/R2R/blob/9c5a94d151f90876bd7eb860f300a8fd662dc481/py/core/main/api/v3/conversations_router.py
- https://www.vulncheck.com/advisories/r2r-missing-ownership-check-allows-modifying-other-users-conversations
9. CVE-2026-82280 `CVSS 7.1`
🎯 受影响:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users
📋 简介:Quivr through 0.0.322 fails to validate ownership in prompt endpoints, allowing authenticated users to modify any prompt by identifier.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-82280
- https://github.com/QuivrHQ/quivr/issues/3698
- https://github.com/QuivrHQ/quivr
- https://github.com/QuivrHQ/quivr/blob/v0.0.322/backend/api/quivr_api/modules/prompt/controller/prompt_routes.py
- https://www.vulncheck.com/advisories/quivr-prompt-endpoints-missing-ownership-validation
10. CVE-2026-61783 `CVSS 7`
🎯 受影响:Wazuh
📋 简介:Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads.
🔗 参考:
- https://nvd.nist.gov/vuln/detail/CVE-2026-61783
- https://github.com/wazuh/wazuh/security/advisories/GHSA-vjcq-cf36-f5gx
- https://github.com/wazuh/wazuh/commit/939f2e52afff8fbeb7b0894f3f1417eb6c395db3
---
新发现 282 条 · 热度升级 0 条 · 🔥=高热度/有 PoC · 🆙=昨日已推、今日热度升级
📊 GitHub 热榜
📊 GitHub 日榜 · 2026-08-29
📋 Agent skill for beautiful, verifiable architecture, workflow, sequence, data-flow, and lifecycle diagrams—self-contained HTML with motion and crisp export.
2. K-Dense-AI/scientific-agent-skills
📋 Turn any AI agent into an AI Scientist. The #1 Agent Skills library for science, used by 175,000+ scientists worldwide. 163 ready-to-use validated skills plus 100+ scientific databases covering biology, chemistry, medicine, and drug discovery. Compatible with Cursor, Claude Code, Codex, Pi, Antigravity, and the open Agent Skills standard.
3. anthropics/claude-plugins-official
📋 Official, Anthropic-managed directory of high quality Claude Code Plugins.
📋 A spy satellite simulator in your browser, except the data is real. Live open source spatial intelligence on a photorealistic 3D globe.
📋 GitNexus: The Zero-Server Code Intelligence Engine - GitNexus is a client-side knowledge graph creator that runs entirely in your browser. Drop in a git repository (Github, Gitlab, Azure, Local) or ZIP file, and get an interactive knowledge graph with a built in Graph RAG Agent. Perfect for code exploration
6. JetBrains/go-modern-guidelines
📋 Help AI coding agents write modern Go
📋 World's first open-source, agentic video production system. 12 production pipelines, 100+ tools, 700+ agent skill and production-knowledge files. Turn your AI coding assistant into a full video production studio.
📋 Drop in a screenshot and convert it to clean code (HTML/Tailwind/React/Vue)
📋 Cursor plugin specification and official plugins
10. freestylefly/awesome-gpt-image-2
📋 Prompt as Code | GPT-Image2 工业级提示词引擎与模板库,530+ 个案例逆向工程,20+ 套工业级模板,并提炼出Skills,持续更新中
🤖 AI 总结分析
今日整体形势呈现“高危漏洞集中爆发、AI 应用与数据基础设施成重点靶标”的特征。高危漏洞预警显示 58 条 CRITICAL 级条目,数量级偏高,且多个漏洞涉及默认配置缺陷、认证绕过与未授权远程代码执行,攻击者利用门槛低、影响面大。安全热点明显向 AI/LLM 开源平台和流数据处理组件倾斜,技术趋势是围绕自动化接口和默认信任边界实施链式利用。
在每日高危漏洞预警中,最值得关注的是 CVE-2026-9198:Langflow 1.0.0 至 1.10.0 版本可被未认证攻击者通过 `/api/v1/auto_login` 铸造 SUPERUSER 令牌,再调用 `/api/v1/validate/code` 执行 `exec()`,形成完整 RCE 链,且参考链接显示已进入 CISA KEV 并存在公开 PoC,现实危害迫在眉睫。另一项 CVE-2026-82266 同样危险:Redpanda 26.2.2 及之前版本将 Admin API 绑定在 `0.0.0.0:9644` 且默认不要求认证,未认证请求被直接视为超级用户,意味着暴露在公网的 Redpanda 实例可被瞬间接管。
每日安全情报今日暂无新增条目,可能与数据源更新节奏或当日事件沉淀不足有关,但这并不代表威胁水平下降,尤其是上述漏洞已存在公开利用迹象,仍需以漏洞预警为行动依据。
GitHub 热榜虽无直接安全工具上榜,但 anthropics/claude-plugins-official 和 K-Dense-AI/scientific-agent-skills 等项目反映出 AI 编码代理的插件与技能库生态正在快速扩张;这些被开发者直接引入本地环境的组件一旦被投毒或引入恶意依赖,将成为新的供应链攻击入口,与今日 AI 平台漏洞风险形成上下游共振。
基于以上分析,今天应优先排查并修复所有暴露在公网的 Langflow 实例,确认版本是否落在 1.0.0 至 1.10.0 区间,并立即升级到 1.8.2 以上版本;若无法即时升级,应先行限制网络访问或关闭相关接口。